fix: do not download and execute binaries via HTTP (#14914)

This fixes a couple of trivial remote code execution opportunities.
This commit is contained in:
Leopold Schabel
2021-01-29 02:59:40 +01:00
committed by GitHub
parent d6873b82ab
commit 31019e9828
3 changed files with 3 additions and 3 deletions

View File

@ -57,7 +57,7 @@ esac
case $TAG in
edge|beta)
DOWNLOAD_URL=http://release.solana.com/"$TAG"/solana-release-$TARGET.tar.bz2
DOWNLOAD_URL=https://release.solana.com/"$TAG"/solana-release-$TARGET.tar.bz2
;;
*)
DOWNLOAD_URL=https://github.com/solana-labs/solana/releases/download/"$TAG"/solana-release-$TARGET.tar.bz2